Privacy Policy

Effective Date: June 23, 2026 Last Updated: June 23, 2026

Important context about the Service this policy covers

GHSLogic is a draft decision-support tool only. Outputs are drafts and require review by a qualified SDS/GHS/regulatory professional before use or distribution. This Privacy Policy describes how we handle data; the Terms of Service describe what the Service is and is not.

This Privacy Policy explains how GHSLogic LLC ("GHSLogic," "we," "us") collects, uses, shares, and protects information when you use the GHSLogic web platform at ghslogic.com (the "Service").

If you have questions or want to exercise privacy rights, contact us at hello@ghslogic.com.

1. Who We Are

GHSLogic LLC is a Maryland limited liability company. For the data we hold about EU/EEA and UK individuals, we act as a data controller for account and billing information and as a data processor for User Content (chemical compositions and uploaded SDS documents) that you upload for processing.

2. What We Collect

2.1 Account Information

  • Name
  • Email address
  • Hashed password
  • Company name and company address (required at registration; used to create your organization and for regulatory documentation such as supplier identification)
  • Account preferences and settings

2.2 User Content

  • Chemical composition data you enter, including ingredient names, CAS numbers, concentrations, and intended uses. This may include trade-secret or confidential business information (CBI). You decide what to upload — please consider whether to redact or obfuscate composition data before upload if you have specific confidentiality concerns.
  • Uploaded SDS documents (PDF and Word) you provide as inputs.
  • Project metadata (project names, notes, classifications, generated drafts).

2.3 Usage Data

  • Pages and features used, actions taken in the app
  • Timestamps and IP addresses
  • Browser type, operating system, device identifiers
  • Referrer URLs and links clicked

2.4 Authentication and Audit Data

  • Login history and sessions
  • Audit log entries for significant actions (e.g., project creation, exports, account changes), with associated IP and timestamp

2.5 Billing Data (handled by Stripe)

  • We do not store raw credit-card or bank-account numbers.
  • Stripe processes payments and provides us with a token, plan status, last-four digits of the card, country, and limited transaction metadata.

2.6 Communications

2.7 Publicly Published SDS Documents (optional feature)

If you choose to use the optional Hosted SDS Publishing feature, the finalized SDS you select — together with associated metadata such as product name and supplier identification — is made available at a public, unauthenticated web address that we host. This content is intended to be public and may be viewed, downloaded, cached, indexed, or archived by anyone (including search engines, if you enable indexing). Publishing is off by default and only occurs when you affirmatively publish a specific SDS; you can withdraw it at any time, though copies already made by third parties are outside our control. See Addendum A of the Terms of Service for the full terms governing this feature.

3. How We Use Information

We use the data we collect to:

  • Deliver the Service, including authentication, project management, and Output generation.
  • Process User Content through Anthropic's Claude API to extract data from supplier SDS documents and to generate draft classifications and content. See Section 4 below for details.
  • Process payments through Stripe.
  • Communicate with you about service updates, security issues, billing, and support.
  • Maintain security, detect abuse, prevent fraud, and enforce our Terms.
  • Improve the Service, in aggregated or de-identified form. We do not use your User Content to train AI models.
  • Comply with legal obligations, respond to lawful requests, and exercise legal rights.

4. AI Processing — Important Disclosure

When you upload SDS documents or enter chemical composition data, the relevant text and data are transmitted to Anthropic, PBC ("Anthropic") for processing through the Claude API to generate Outputs. This is essential to how the Service works.

What you should know:

  • What is sent. The text content of uploaded SDS documents (extracted from PDFs/Word files), the chemical composition data you enter, and instructions necessary to generate the Output.
  • Why. To extract structured information from supplier SDS documents and to generate draft hazard classifications, draft SDS sections, and other Outputs.
  • Anthropic's role. Anthropic acts as a subprocessor. Anthropic does not use your inputs to train its general models when processed through the API for commercial customers under Anthropic's standard API terms. We rely on Anthropic's published policies and Data Processing Agreement (where applicable) for this assurance.
  • Where. Anthropic processes data on infrastructure that may be located in the United States.
  • Your control. If you do not want chemical composition data or supplier SDS text transmitted to Anthropic, do not upload that data to GHSLogic. The Service cannot generate Outputs without this transmission.

If Anthropic's terms or your requirements change, you should review whether continued use of the Service is appropriate for your data.

5. Third-Party Service Providers (Subprocessors)

We share information with the vendors below as necessary to deliver the Service. Each operates under contractual confidentiality and security obligations.

Vendor Role Data received Region
Supabase Database and file storage Account info, User Content, audit logs US
Google Cloud (Cloud Run) Backend API hosting Service traffic, IP addresses, request payloads in transit US
Vercel Frontend hosting and edge delivery Service traffic, IP addresses, browser metadata US/Global edge
Anthropic AI processing (Claude API) SDS document text and chemical composition data submitted for processing US
Stripe Payment processing Name, email, billing address, payment-method details (Stripe-hosted) US/EU
Resend Transactional email delivery Email address and message content (e.g., verification, password reset, alerts) US
Sentry Error monitoring Error events with IP and limited technical metadata; request bodies, cookies, authentication headers, and query strings are scrubbed before transmission US

We will update this list when we add or replace a subprocessor.

We also disclose information when required by law, in response to valid legal process, to protect rights and safety, or in connection with a corporate transaction (merger, acquisition, financing) — in which case we will require the recipient to honor this Privacy Policy or provide notice of any changes.

We do not sell personal information.

6. Data Retention

Data type Retention
Account information While your account is active; deleted on account deletion (subject to legal hold)
User Content (projects, compositions, uploads, Outputs) While your account is active; deleted on account deletion
Audit logs and login history Retained while your account is active and for a reasonable period thereafter for security, abuse-prevention, and dispute purposes; deleted on account deletion (subject to legal hold)
Billing records As required by Stripe and applicable tax/financial laws (typically 7 years)
Support communications Up to 3 years for service-quality and dispute purposes
Backups Supabase automated backups retained per Supabase's default retention; backup data is overwritten on a rolling schedule

You may delete your account in-app under Account → Security, which initiates deletion of account and User Content within 30 days, except where retention is required by law.

For full details, see our Data Retention and Deletion Policy.

7. Your Rights

Subject to applicable law, you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your account and associated data (in-app under Account → Security, or by request);
  • Restrict or object to certain processing;
  • Port your data in a machine-readable format;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with a supervisory authority.

To exercise any of these rights, email hello@ghslogic.com (subject: "Privacy Request"). We will respond within the timeframes required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA, extendable as permitted).

We will verify your identity before honoring requests, typically by confirming control of the registered email address.

8. GDPR — For EU/EEA and UK Users

8.1 Lawful Bases

We process personal data on these bases:

  • Performance of a contract (Article 6(1)(b)) — to provide the Service you signed up for;
  • Legitimate interests (Article 6(1)(f)) — security, fraud prevention, service improvement;
  • Legal obligation (Article 6(1)(c)) — tax, accounting, response to lawful requests;
  • Consent (Article 6(1)(a)) — for any processing where we ask for it.

8.2 International Transfers

Data is transferred to the United States and processed there. Where applicable, we rely on the EU Standard Contractual Clauses with subprocessors and supplemental measures (encryption in transit and at rest, access controls). Where Anthropic, Supabase, Google Cloud, Vercel, Stripe, Resend, or Sentry offers a Data Processing Agreement, we maintain one or rely on the published DPA.

8.3 Data Processing Agreements

Business customers requiring a DPA from GHSLogic may request one at hello@ghslogic.com.

9. CCPA / CPRA — For California Users

In the prior 12 months, we have collected the categories of personal information described in Section 2 (identifiers, commercial information, internet/network activity, professional information, and User Content). We collect this information for the business purposes described in Section 3 and disclose it to the subprocessors in Section 5.

We do not sell personal information and do not share personal information for cross-context behavioral advertising.

California residents have the right to:

  • Know what personal information we collect, use, and disclose;
  • Delete personal information (subject to exceptions);
  • Correct inaccurate personal information;
  • Limit the use of sensitive personal information;
  • Non-discrimination for exercising these rights.

To submit a request, email hello@ghslogic.com. Authorized agents may submit requests with proof of authorization.

10. Cookies and Local Storage

We use a small number of mechanisms to keep the Service working:

  • JWT session token stored in your browser's localStorage to keep you signed in.
  • Strictly necessary cookies for security and load balancing where required.
  • No advertising cookies. No third-party tracking pixels.

We do not currently use third-party analytics that profile individual users. If we add analytics in the future, we will update this Policy and (where required) ask for consent.

You can clear localStorage and cookies via your browser settings; doing so will sign you out.

11. Security

We use, among other measures:

  • Encryption at rest for database and file storage (AES-256 via Supabase);
  • TLS 1.2+ for all data in transit;
  • Multi-factor authentication available for user accounts;
  • Rate limiting and abuse detection on authentication endpoints;
  • Audit logging of significant events with IP and timestamp;
  • Least-privilege access controls for GHSLogic personnel;
  • Ongoing dependency vulnerability scanning and periodic security reviews.

No system is perfectly secure. You are responsible for protecting your credentials and using reasonable security practices on your end (strong unique passwords, MFA, up-to-date browsers).

12. Children's Privacy

The Service is intended for adult professional users and is not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected such information, we will delete it.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new "Last Updated" date and, for material changes, provide notice (e.g., by email or in-app banner) at least 14 days before the change takes effect.

14. Contact

GHSLogic LLC Email for privacy matters: hello@ghslogic.com (subject line: "Privacy Request") Website: ghslogic.com

If you are in the EU/EEA or UK, you have the right to lodge a complaint with your local data protection authority.